Access Control Owner Transfer in Wireless M2M Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In M2M communication systems, when an M2M server account is deleted, existing technologies face challenges in efficiently managing access rights and resources, leading to difficulties in continuous access control and resource management due to the deletion of access rights, which can result in resources becoming inaccessible.
Innovation Solution
A method for processing resources associated with a deleted server account in a wireless communication system, involving the deletion of access control objects, changing the access control owner based on the highest sum of access rights among other servers, and transmitting notifications for access control changes, while also handling configuration information related to 'observe' operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If an M2M server account is deleted, then the server account and its associated resources are removed from the system, but access control rights become invalid and resources become inaccessible
Solution Approach 1:
The patent performs preliminary actions by identifying and designating a new access control owner before the server account is completely deleted. The terminal device determines which server should become the new owner based on pre-established criteria (such as observation relationships or access control lists), ensuring that access control rights are seamlessly transferred and maintained throughout the deletion process, preventing any access control gaps.
2Ease of manufacture
If access control rights are removed upon server deletion, then the server account is fully deleted, but resources associated with that server become inaccessible and management is disrupted
Solution Approach 1:
The patent introduces an intermediary mechanism where the terminal device acts as a mediator between the deleting server and the resources. Instead of directly removing access control rights when a server is deleted, the terminal device intermediates by automatically designating a new access control owner from among remaining servers, thereby maintaining continuous access control and ensuring resources remain accessible through the new owner.
3Quantity of substance
If a server is deleted from the system, then the server account is removed, but determining the new access control owner becomes complex and time-consuming
Solution Approach 1:
The patent establishes preliminary criteria and mechanisms for determining the new access control owner before deletion occurs. The terminal device maintains observation relationships and access control lists that pre-identify candidate servers, allowing for rapid automatic designation of a new owner when deletion happens, thus minimizing the time required for access control owner determination.
4Reliability
If access control ownership is transferred automatically, then resource accessibility is maintained, but the complexity of access control management increases
Solution Approach 1:
The patent implements a self-service mechanism where the terminal device automatically performs the entire access control owner transfer process without requiring manual intervention. The terminal device autonomously identifies candidate servers, determines the appropriate new owner based on pre-established criteria, and completes the transfer of access control rights, thereby maintaining continuous access control while minimizing the operational complexity for users.
Data Source
Figure 1~2
Figure 3(a)~3(d)
Figure 4~5
AI summary
Provided is a method for processing a specific object instance associated with a server due to a server account deletion in a wireless communication system, according to one embodiment of the present invention, wherein the method is performed by a terminal and comprises the steps of: receiving from a first server an action command for deleting an account of a specific server; deleting the specific object instance and an access control object instance associated with same when the specific object instance is an object instance accessible only to the specific server, and deleting access authorization information of the specific server from the access control object instance associated with the specific object instance when the specific object instance is an object instance accessible by a plurality of servers including the specific server; and changing the server having the largest sum of values granted to an access authorization of each of the plurality of servers, with the exception of the specific server as the access control owner, when the specific server is the only access control owner of the access control object instance.